Impact
The AMDGPU DRM driver contains a routine that frees the previous CRTC state before allocating a new one. When the allocation fails, the function returns early without updating the state pointer, leaving a dangling reference to already freed kernel memory. This creates a use‑after‑free condition that can corrupt kernel memory when the stale pointer is later accessed. The corruption may allow an attacker to overwrite critical kernel structures, potentially leading to control‑flow hijack or kernel panic. The likely attack vector is an entity that can trigger a memory allocation failure and subsequently cause the driver to use the dangling pointer, typically implying local privileged execution or an existing kernel exploitation chain. An attacker would need to exercise control over the display subsystem, which is usually limited to privileged users or compromised processes.
Affected Systems
All Linux kernel builds that include the AMDGPU DRM driver are affected. The vulnerability exists in the amdgpu_dm_crtc_reset_state routine prior to the patch; the security fix is present in later kernel releases but no specific version numbers are provided in the advisory. Systems running patched kernels are no longer susceptible.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity for kernel memory corruption. The EPSS score of less than 1% suggests that, at present, exploitation in the wild is unlikely. The vulnerability is not listed in CISA's KEV catalog. Because the flaw requires an allocation failure and a subsequent use of the stale pointer, the difficulty of exploitation is not trivial, but once achieved, the impact can be critical, providing a path to privilege escalation or denial of service.
OpenCVE Enrichment